GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,963
Erlang
39
GitHub Actions
38
Go
2,615
Maven
5,000+
npm
4,255
NuGet
760
pip
4,036
Pub
12
RubyGems
953
Rust
1,049
Swift
45
Unreviewed advisories
All unreviewed
5,000+
991 advisories
Filter by severity
Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics...
Critical
Unreviewed
CVE-2025-54451
was published
Jul 23, 2025
Livewire is vulnerable to remote command execution during component property update hydration
Critical
CVE-2025-54068
was published
for
livewire/livewire
(Composer)
Jul 17, 2025
Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
Critical
Unreviewed
CVE-2025-53867
was published
Jul 17, 2025
The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up...
Critical
Unreviewed
CVE-2025-5396
was published
Jul 17, 2025
A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a...
Critical
Unreviewed
CVE-2025-34127
was published
Jul 17, 2025
pyLoad vulnerable to XSS through insecure CAPTCHA
Critical
CVE-2025-53890
was published
for
pyload-ng
(pip)
Jul 15, 2025
XWiki Rendering is vulnerable to RCE attacks when processing nested macros
Critical
CVE-2025-53836
was published
for
org.xwiki.rendering:xwiki-rendering-transformation-macro
(Maven)
Jul 14, 2025
The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to...
Critical
Unreviewed
CVE-2025-5392
was published
Jul 11, 2025
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that...
Critical
Unreviewed
CVE-2025-34077
was published
Jul 9, 2025
SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This...
Critical
Unreviewed
CVE-2025-42967
was published
Jul 8, 2025
Insufficient security mechanisms for created containers in educoder challenges v1.0 allow...
Critical
Unreviewed
CVE-2025-45479
was published
Jul 7, 2025
Remote attackers can execute arbitrary code in the context of the vulnerable service process.
Critical
Unreviewed
CVE-2025-5333
was published
Jul 6, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson Easy...
Critical
Unreviewed
CVE-2025-49302
was published
Jul 4, 2025
An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote...
Critical
Unreviewed
CVE-2025-34089
was published
Jul 3, 2025
A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to...
Critical
Unreviewed
CVE-2025-34061
was published
Jul 3, 2025
An authenticated remote code execution vulnerability exists in Lucee’s administrative interface...
Critical
Unreviewed
CVE-2025-34074
was published
Jul 2, 2025
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0...
Critical
Unreviewed
CVE-2025-37099
was published
Jul 1, 2025
Improper Control of Generation of Code ('Code Injection') vulnerability in bitto.Kazi Custom...
Critical
Unreviewed
CVE-2025-49029
was published
Jul 1, 2025
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management...
Critical
Unreviewed
CVE-2025-34046
was published
Jun 26, 2025
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via...
Critical
Unreviewed
CVE-2024-37743
was published
Jun 24, 2025
An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute...
Critical
Unreviewed
CVE-2023-48978
was published
Jun 23, 2025
On a client with a non-admin user, a script can be integrated into a report. The reports could...
Critical
Unreviewed
CVE-2025-6512
was published
Jun 23, 2025
Pterodactyl Panel Allows Unauthenticated Arbitrary Remote Code Execution
Critical
CVE-2025-49132
was published
for
pterodactyl/panel
(Composer)
Jun 19, 2025
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated...
Critical
Unreviewed
CVE-2025-23121
was published
Jun 19, 2025
ProTip!
Advisories are also available from the
GraphQL API